Are you need IT Support Engineer? Free Consultant

Pass Cyber Essentials Plus in 6–12 Weeks: UK NCSC Pre Audit Checklist

  • By Rebecca Smith
  • September 1, 2026
  • 4 Views

Cyber Essentials Plus is the audited, higher-assurance tier of the UK government-backed Cyber Essentials scheme, verified through independent technical testing rather than self-declaration. Choose it when procurement, a client contract, cyber insurance, or a board risk register demands proof that your five core controls actually work in practice, not just on paper. If none of those pressures apply yet, the standard self-assessed certificate may still be enough for now.


TL;DR:

  • Cyber Essentials Plus involves independent testing of five core security controls, including external scans, internal checks, and privilege validation.
  • The audit process requires thorough evidence such as configuration documentation, patch records, and proof of multi-factor authentication on cloud admin accounts.
  • It is essential to define and agree on the scope, especially for cloud services and personal devices, to avoid delays and extra costs during assessment.
  • Cost typically ranges from £1,500 to £8,000 plus VAT, influenced by device count, sites, and cloud complexity, with more extensive infrastructure requiring more assessor time.
  • Preparing for the audit involves conducting internal vulnerability scans, verifying endpoint protection, and building a comprehensive evidence pack before scheduling the assessment.

Table of Contents

What Cyber Essentials Plus covers and how it differs from Cyber Essentials

Cyber Essentials exists to reduce the most common internet-borne threats facing UK organisations, and it does so by testing five technical controls rather than trying to cover every conceivable risk. The base certification, Cyber Essentials, relies on a Verified Self Assessment: you complete a questionnaire, a Certification Body checks it, and you receive a certificate based on your own answers.

Cyber Essentials Plus tests the same five controls but replaces self-declaration with independent verification. An assessor runs external scans, authenticated internal checks and hands-on tests against your actual infrastructure. You cannot jump straight to CE+ either. Most Certification Bodies require a current Cyber Essentials verified self-assessment certificate in place, and you typically need to apply for CE+ within three months of that certificate being issued, so the two schemes sit on a tight, sequential timeline rather than as independent options.

What the audit day actually tests

The Cyber Essentials Plus Test Specification v3.2 sets out exactly what an assessor checks, and it is more forensic than most IT teams expect on their first run through it.

  • External vulnerability scans of every internet-facing IP address and domain, looking for open ports, outdated services and missing patches visible from outside your network.
  • Authenticated internal scans run against a representative sample of end-user devices and servers, logged in with normal user credentials rather than admin rights, to see what an attacker could exploit post-compromise.
  • Malware and phishing simulation tests, where the assessor attempts to run benign test files and malicious-looking email or browser downloads to confirm your endpoint protection actually blocks them.
  • Account separation and privilege checks, confirming day-to-day admin work does not happen on standard user accounts.
  • Multi-factor authentication checks on cloud administrative accounts, a control area assessors now scrutinise closely given how many breaches trace back to a single compromised admin login.

Sampling rules matter here. The requirements for IT infrastructure require every operating system type in use, and every distinct device class, to be represented in the sample. You cannot present three identical laptops and call it representative if your estate also includes tablets, a Linux server and a handful of Macs.

The five controls and how to define your scope

Cyber Essentials Plus is built around five technical controls, and each one needs concrete evidence, not a policy statement. Firewalls and boundary devices need documented configuration proof; where a boundary device cannot be used, such as with some cloud-only setups, host-based firewalls on individual devices must fill the gap. Secure configuration means an up-to-date asset inventory, unused services disabled, and no default credentials on admin interfaces. Security update management requires a patch policy plus evidence that high and critical vulnerabilities are remediated within expected windows, usually within 14 days of a patch becoming available. User access control demands least-privilege accounts, separate admin logins, and multi-factor authentication on every cloud admin role. Malware protection means EDR or antivirus coverage across the estate, with application allow-listing where the organisation relies on it instead.

  • Cloud services are always in scope. There is no opting out of a control simply because a provider hosts the workload.
  • Document your scope decision, whether you certify the whole organisation or a justified sub-set, and agree it formally with your Certification Body before testing begins.
  • Bring-your-own-device policies need particular care, since personal devices used for work email or file access typically fall inside scope too.

Our cybersecurity essentials guide walks through scope boundary decisions in more depth, particularly for organisations running hybrid cloud and on-premise environments side by side.

Pro Tip: Agree your scope statement in writing with your Certification Body before you book a testing date. A vague or overly broad scope is one of the most common reasons assessments run over budget, because the assessor ends up sampling far more devices than necessary.

Timeline and typical cost for UK organisations

Budget six to twelve weeks end-to-end, and treat that as a realistic minimum rather than a worst case — our prompt injection defense checklist can help structure your project timeline and risk management effectively. IT directors consistently underestimate how long evidence collection takes, particularly when patch records and MDM screenshots are scattered across multiple systems.

A typical schedule runs through five stages:

  • Preparation and gap analysis, checking current controls against the test specification.
  • Submitting the Verified Self Assessment, the prerequisite certificate CE+ builds on.
  • External scanning, usually scheduled a few days ahead of the audit day itself.
  • Remediation, fixing anything the scans or gap analysis flagged.
  • Audit day and certification, when the assessor runs the full CE+ test suite on site or remotely.

Cost varies with device count, number of sites and cloud complexity, and industry estimates put typical UK small and mid-sized budgets generally fall into a broad range plus VAT, though every quote is scoped individually. CE+ costs more than the self-assessment for a straightforward reason: an assessor has to physically test your infrastructure, sample devices by hand, and run authenticated scans that take hours rather than the minutes a questionnaire needs. IASME confirms that assessor time and sampling requirements are the main driver of the price gap between the two tiers.

Pre-audit checklist: what to do before testing day

Work through these in order, and do not skip ahead to booking your audit date until the earlier steps are genuinely complete.

  1. Confirm your scope and check your Verified Self Assessment certificate is current and within the window your Certification Body requires for CE+ progression.
  2. Run your own authenticated vulnerability scans using a tool such as Nessus, OpenVAS or Tenable, and remediate every high and critical finding before the assessor arrives.
  3. Verify full endpoint protection coverage. Confirm EDR or antivirus is deployed and reporting correctly across every device class, and screenshot the management console as evidence.
  4. Enable multi-factor authentication on all cloud admin accounts and document how standard user accounts are kept separate from privileged ones.
  5. Prepare your patch management evidence, including the policy document and logs showing remediation timescales for recent high and critical vulnerabilities.
  6. Rehearse the observation-based tests, such as opening a benign malware sample or a phishing-style attachment, so your team knows what the assessor will attempt and what a correct block looks like.
  7. Build a single evidence pack covering configuration screenshots, the leaver process, and MDM records, so assessor questions on the day get answered in minutes rather than triggering a scramble.

Pro Tip: Keep every piece of evidence in one shared folder structured by control, not by device. Assessors ask questions control by control, and hunting through device-by-device folders under time pressure is where most delays on audit day come from.

Our guide to improving IT security covers practical rollout advice for several of these controls, particularly patch management and endpoint protection.

How pass, fail and remediation actually work

A single failed sub-test normally means an overall fail, since the test specification treats each control as pass or fail with only narrow discretion for Certification Bodies to allow minor exceptions. Most organisations get 30 days to remediate findings before a rescan is required, and any high or critical vulnerability must be fixed and reverified within that window rather than simply noted for later.

Once you pass, expect certification within a short turnaround, and keep your evidence on file for the certificate’s full lifetime since Certification Bodies can request it again. Procurement teams increasingly ask for CE+ specifically, including some public-sector contracts, and cyber insurers now routinely reference it when assessing risk and setting premiums.

How pass, fail and remediation actually work — overview diagram

Where Re-solution sees organisations trip up

Most CE+ failures we encounter trace back to three things: partial EDR rollouts that miss a handful of legacy devices, cloud admin accounts without MFA enabled, and patch records that exist but cannot be produced quickly enough on audit day. A structured gap analysis before the assessor ever gets involved catches all three. Managed patching and MFA deployment, run as short remediation sprints rather than open-ended projects, consistently cut both the assessor’s time on site and the number of findings that need a second pass.

— Jacob

How Re-solution supports your Cyber Essentials Plus readiness

Getting from “we think we’re ready” to a passed audit usually comes down to closing gaps before the assessor finds them, not during remediation afterwards. Re-solution’s network audit service runs a pre-audit gap analysis against the five CE+ controls, flagging weak firewall configurations, incomplete patching and missing MFA coverage while there is still time to fix them without a rescan penalty.

Re-solution

Beyond the initial review, managed IT services from Re-solution cover the ongoing work that keeps certification current between renewals: patch management, EDR deployment and ordinary account hygiene checks. If MFA coverage on your cloud admin accounts is the gap holding you back, our guide to multi-factor authentication sets out deployment options that suit most Microsoft 365 and Google Workspace environments. Read more on how sound IT infrastructure underpins a smooth assessment, then get in touch to book a pre-audit review and put a realistic certification date on the calendar.

Where to find the official Cyber Essentials guidance

Consult the NCSC’s Cyber Essentials resources for the current requirements documents, test specification, and IASME guidance before briefing your assessor or procurement team.

Sources

FAQ

How much does Cyber Essentials Plus cost in the UK?

Costs vary by device count, site number and cloud complexity, but UK market estimates put typical budgets between £1,500 and £8,000 plus VAT; every quote is scoped to your specific infrastructure.

Is Cyber Essentials internationally recognised?

Cyber Essentials is a UK government scheme primarily recognised within the UK, particularly for public-sector procurement, though many international clients and insurers increasingly accept it as evidence of baseline security maturity.

How do I check if a company holds Cyber Essentials Plus?

Ask the organisation directly for their certificate, or check with their Certification Body; certificates carry an expiry date and scope statement that should match the services they provide you.

Is Cyber Essentials Plus worth it?

For organisations handling sensitive data, bidding for contracts that require it, or seeking better cyber insurance terms, CE+ delivers independently verified proof of security controls that the self-assessed certificate cannot provide on its own.

How does Cyber Essentials Plus compare to ISO 27001?

CE+ verifies five specific technical controls through hands-on testing, while ISO 27001 assesses a broader information security management system; many UK organisations pursue CE+ first as a faster, more affordable step before considering broader certifications such as ISO 27001.